← Pricing / Starter
Starter - 99 EUR
A single automated scan of your public perimeter. 15 security controls checked. PDF delivered in 24 hours.
What you get
- TLS configuration audit (cipher suites, certificate chain, HSTS, OCSP stapling)
- HTTP security headers check (CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy)
- Cookie flags audit (Secure, HttpOnly, SameSite)
- DNS security (SPF, DKIM, DMARC, CAA, DNSSEC)
- Subdomain enumeration via certificate transparency
- Exposed panel detection (admin, wp-login, phpmyadmin, .git)
- Open port scan of published IPs (top 1000)
- Technology fingerprint with CVE cross-reference
- Content-Security-Policy parser + rating
- Public bucket scan (S3, GCS, Azure Blob)
- Email header policy (DMARC alignment, reject policy)
- Known-breach exposure check (HaveIBeenPwned domain)
- Certificate expiration + weak-crypto flags
- robots.txt + sitemap.xml information disclosure
- Third-party script audit (integrity, origin, privacy)
What you do NOT get
- Manual triage or engineer review
- Exploitation attempts
- Authenticated testing
- Remediation support
- NDA or written engagement letter
If you need any of the above, the Standard tier starts at 799 EUR and includes 8 hours of engineer review.
Order now — EUR 99
Card checkout via Stripe. Scan starts within 24 hours of payment clearing. PDF emailed to the address you use at checkout.
What happens next
- Stripe confirms payment (Apple Pay / Google Pay / card).
- Scoping email reaches you within 60 seconds.
- Reply with any authentication or scope notes (optional).
- Scan runs within 24 hours. PDF delivered to the email on your order.
Refund policy
If the scan cannot reach your domain (DNS misconfiguration, rate limit, geo-block), you get a full refund. If findings are disputed, we re-run the specific check at no charge. Once the PDF is delivered, the engagement is considered complete.